Under NIST SP 800-30 Rev. 1, what are the four steps of a risk assessment, and how does ISO 27005 structure the same work?
answer
- guide for conducting risk assessments
- prepare before you conduct
- six conduct tasks end in risk
- assessment is never one-time
- context, assess, treat, accept
basics
~20 sNIST SP 800-30 Rev. 1 runs prepare, conduct, communicate results and maintain; conducting identifies threat sources, threat events, vulnerabilities, likelihood, impact and finally risk. ISO/IEC 27005 frames the same work as context, identification, analysis, evaluation, treatment and acceptance, with continual monitoring.
solid answer
~50 sSP 800-30 Rev. 1 (September 2012) is NIST's guide to the *assess* component of the frame-assess-respond-monitor cycle from SP 800-39. Its four steps are: **Prepare** — purpose, scope, assumptions and constraints, information sources, and the risk model and analytic approach (Tasks 1-1 to 1-5); **Conduct** — threat sources, threat events, vulnerabilities and predisposing conditions, likelihood, impact, and risk as a combination of the two (Tasks 2-1 to 2-6); **Communicate** results to decision makers and share supporting information (Tasks 3-1, 3-2); **Maintain** — monitor risk factors and update the assessment (Tasks 4-1, 4-2). ISO/IEC 27005 is the ISO guidance behind ISO 27001's risk requirements: establish context, then risk assessment as identification, analysis and evaluation, then treatment and acceptance, wrapped in communication and consultation and monitoring and review. Both treat assessment as iterative, not a one-off report.
go deeper
Recall the four SP 800-30 steps in order and that ISO 27005 is guidance supporting ISO 27001, not a certificate of its own.
Explain what each step produces, including the Prepare choices of risk model, assessment approach and analysis approach, and map the steps onto ISO 27005's phases.
Show how you run a repeatable assessment: fixing scales and tolerance up front, making uncertainty explicit in the results, and keeping the assessment maintained as systems change.
Discuss choosing between NIST and ISO methods for an organization pursuing several frameworks, and how one assessment process can serve both without duplicating work.
## Where SP 800-30 sits **NIST SP 800-30 Rev. 1, *Guide for Conducting Risk Assessments*** (September 2012) is guidance, not a certification. It describes one component of the risk management process defined in **SP 800-39**, which has four components: **frame** (assumptions, constraints, risk tolerance, priorities), **assess**, **respond** and **monitor**. SP 800-30 covers the *assess* component only; choosing a risk response is a separate component, which the assessment informs. Assessments can be run at three tiers: Tier 1 (organization), Tier 2 (mission or business process) and Tier 3 (information system). For US federal systems it is the assessment guidance behind SP 800-53 control `RA-3` and the Risk Management Framework; for everyone else it is voluntary guidance that many programmes adopt. ## The four steps | Step | Tasks | What happens | |---|---|---| | **1. Prepare for the assessment** | 1-1 to 1-5 | Identify the purpose, the scope, the assumptions and constraints, the sources of threat, vulnerability and impact information, and the risk model and analytic approach | | **2. Conduct the assessment** | 2-1 to 2-6 | Identify threat sources, threat events, vulnerabilities and predisposing conditions; determine likelihood, adverse impact, and then risk | | **3. Communicate results** | 3-1, 3-2 | Communicate results to decision makers to support risk responses; share risk-related information with appropriate personnel | | **4. Maintain the assessment** | 4-1, 4-2 | Monitor the risk factors on an ongoing basis; update the assessment with what monitoring finds | Task 2-6 determines risk "as a combination of likelihood and impact" and asks the assessor to make uncertainty explicit, including assumptions and subjective judgements. ## Decisions made in Prepare Prepare is where most quality is won or lost. Two choices shape everything after: - **Assessment approach** — *quantitative*, *qualitative* or *semi-quantitative* (section 2.3.2). Qualitative scales support communication but compress results; quantitative results support cost-benefit analysis of alternative responses but lose rigour when subjective judgements are buried in them. - **Analysis approach** — *threat-oriented*, *asset/impact-oriented* or *vulnerability-oriented*: which of the risk factors the analysis starts from. The risk model, value scales and the organization's risk tolerance are fixed here so that different assessors produce comparable results. ## The ISO/IEC 27005 parallel **ISO/IEC 27005** (current edition 2022) is the ISO guidance for information security risk management and supports the risk assessment and treatment requirements of ISO/IEC 27001. It is not a certification; an organization is certified against ISO 27001 and may use any method that meets that standard's requirements. The standard is paywalled, so its structure is described here without clause numbers: 1. **Context establishment** — scope, criteria for risk acceptance and for performing assessments. 2. **Risk assessment**, split into identification, analysis and evaluation against the criteria. 3. **Risk treatment** — choosing options and producing a treatment plan. 4. **Risk acceptance** of the residual risk by the risk owners. 5. Around all of these, **communication and consultation** and **monitoring and review**. The 2022 edition describes both an **event-based** approach (start from scenarios) and an **asset-based** approach (start from assets, threats and vulnerabilities) to identification. ## Mapping the two | NIST SP 800-30 / 800-39 | ISO/IEC 27005 | |---|---| | Frame (in SP 800-39) and Prepare | Context establishment | | Conduct, Tasks 2-1 to 2-3 | Risk identification | | Conduct, Tasks 2-4 to 2-6 | Risk analysis and evaluation | | Respond (SP 800-39, outside SP 800-30) | Risk treatment and acceptance | | Communicate | Communication and consultation | | Maintain | Monitoring and review | The main difference in emphasis: SP 800-30 treats the assessment as a self-contained activity feeding a separate response component, and gives detailed tables for adversarial threat characteristics (capability, intent, targeting). ISO 27005 puts treatment and acceptance in the same process description. ## Common misreadings - Treating the report as the end; SP 800-30's fourth step exists because risk factors change. - Skipping Prepare and arguing about ratings later because nobody fixed the scales. - Assuming ISO 27001 requires ISO 27005 verbatim; it requires a defined, repeatable process that produces consistent, valid and comparable results.
- Which SP 800-30 step do programmes most often neglect, and what does that cost?Maintain. Teams run a thorough assessment, issue the report and stop, so ratings drift away from reality as systems, threats and controls change. Tasks 4-1 and 4-2 call for monitoring the risk factors and updating the assessment, which is what lets a risk owner rely on a rating months later instead of commissioning a new assessment from scratch.
- In SP 800-30, what is the difference between the assessment approach and the analysis approach?The assessment approach is the value scale: quantitative, qualitative or semi-quantitative. The analysis approach is the starting point for reasoning: threat-oriented, asset/impact-oriented or vulnerability-oriented. Both are chosen in Prepare (Task 1-5) together with the risk model, and they are independent: a threat-oriented analysis can be scored on a qualitative or a quantitative scale.
saying these in an interview costs you the question
- A risk assessment is finished once the report is delivered.
- SP 800-30 is a certification an organization can be audited against.
- ISO 27001 certification requires following ISO 27005 exactly.
- Choosing the risk response is one of the SP 800-30 assessment steps.
- The risk model can be chosen after the ratings are in.